Description
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.
Published: 2026-07-09
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Remote Collector configuration process generates a file that disables TLS certificate verification for the Guardian or CMC endpoints, and the tool provides no option to enable it. This misconfiguration allows an attacker positioned between the Collector and the Guardian/CMC to perform a man‑in‑the‑middle attack. The attacker could intercept or modify the sync token, impersonate the server, inject spoofed asset or vulnerability data, or disrupt the communication flow, compromising confidentiality, integrity, and availability.

Affected Systems

Nozomi Networks Remote Collector versions prior to v26.2.0 are affected. Any installation of the Remote Collector that uses the n2os‑tui interface to configure a Guardian or CMC will inherit the disabled TLS validation unless it is manually corrected.

Risk and Exploitability

The CVSS score of 8.3 reflects significant impact. The EPSS score of <1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the attack vector is a network‑level man‑in‑the‑middle that requires only proximity to the network segment between the Remote Collector and the Guardian or CMC; no authentication or privileged access is needed. The lack of certificate verification provides a clear path for an attacker to intercept traffic, making the risk moderate to high for any organization that relies on the Remote Collector to transmit sensitive information.

Generated by OpenCVE AI on July 29, 2026 at 12:42 UTC.

Remediation

Vendor Solution

Upgrade to v26.2.0 or later.


Vendor Workaround

Manually edit the "n2os.conf.user" file in the Remote Collector and remove the "!" prefix from the upstream Guardian or CMC endpoint entry to enable TLS certificate verification.


OpenCVE Recommended Actions

  • Upgrade the Remote Collector to version v26.2.0 or later to enable TLS certificate verification by default.
  • Edit the n2os.conf.user file in the Remote Collector and remove the "!" prefix manually enable TLS certificate verification.
  • Implement network segmentation or firewall controls to limit access to Guardian/CMC endpoints.

Generated by OpenCVE AI on July 29, 2026 at 12:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.
Title Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0
First Time appeared Nozomi Networks
Nozomi Networks remote Collector
Weaknesses CWE-671
CPEs cpe:2.3:a:nozomi_networks:remote_collector:*:*:*:*:*:*:*:*
Vendors & Products Nozomi Networks
Nozomi Networks remote Collector
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N'}


Subscriptions

Nozomi Networks Remote Collector
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2026-07-09T12:30:59.025Z

Reserved: 2026-03-10T16:14:03.266Z

Link: CVE-2026-31985

cve-icon Vulnrichment

Updated: 2026-07-09T12:30:54.497Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-671

    Lack of Administrator Control over Security